CWE-285
1,431 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CVEs (1,431)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian Fuse ProjectRedhat5Debian Linux Enterprise Linux DesktopEnterprise Linux Server+2 moreNov 21, 2024 Jul 24, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option rega...Show more |
1Cisco 3Mobility Services Engine 3310 Firmware Mobility Services Engine 3355 FirmwareMobility Services Engine 3365 FirmwareNov 21, 2024 Jul 18, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A Read-Only User Effect Change vulnerability in the Policy Builder interface of Cisco Policy Suite could allow an authenticated, remote attacker to make policy changes in the Policy Builder interface. The vulnerability i...Show more |
3Canonical DebianPolkit Project3Debian Linux PolkitUbuntu LinuxNov 21, 2024 Jul 10, 2018 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unre...Show more |
4Ceph DebianOpensuse+1 more9Ceph Ceph StorageCeph Storage Mon+6 moreNov 21, 2024 Jul 10, 2018 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous...Show more |
Improper authorization vulnerability in Highlight Preview in Synology Universal Search before 1.0.5-0135 allows remote authenticated users to bypass permission checks for directories in POSIX mode. |
1Redhat 4Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+1 moreNov 21, 2024 Jul 3, 2018 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /etc/shells. This violates security assumptions made by pam_shells and some daemons which allow acces...Show more |
Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been designed to achieve security purposes and therefore does not include any encryptio...Show more |
1Sybase 1Adaptive Server Enterprise Nov 21, 2024 Apr 24, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Backup Server component in SAP Sybase ASE 15.7 before SP51 allows remote attackers to bypass access restrictions and perform database dumps by leveraging failure to validate credentials, aka SAP Security Note 1927859...Show more |
A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4. If a user account using OAuth2 authentication method was once confirmed but later suspended, the user could still login to the site. |
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users. |
2Debian Gitlab2Debian Linux GitlabNov 21, 2024 Mar 21, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user login. |
1Ibm 1Business Process Manager Nov 21, 2024 Mar 15, 2018 N/A· v4 4.3 MEDIUM· v3 5.5 MEDIUM· v2 IBM Business Process Manager 7.5.x, 8.0.x, 8.5.0, 8.5.5, and 8.5.6.0 through cumulative fix 2 allow remote authenticated users to delete process and task data by leveraging incorrect authorization checks. IBM X-Force ID:...Show more |
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker c...Show more |
In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did not have permissions l...Show more |
1Trendmicro 1Smart Protection Server Nov 21, 2024 Jan 19, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthenticated attacker to hijack active user sessions to perform authentica...Show more |
1Phoenixcontact 29Fl Switch 3004t Fx Firmware Fl Switch 3004t Fx St FirmwareFl Switch 3005 Firmware+26 moreNov 21, 2024 Jan 12, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to craft special HTTP...Show more |
It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker...Show more |
Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization |
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain privileges by leveraging failure to properly enforce authorization checks. |
1Sierra Wireless 2Airlink Raven Xe Firmware Airlink Raven Xt FirmwareMay 13, 2026 Jun 30, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can be accessed without...Show more |